CVE-2025-22037

🟡 Monitoruj

Dereferencja wskaźnika null w ksmbd pozwala na zdalne wywołanie błędów w sesji SMB2.

CVSS
7.5
EPSS
69.6%
Exploit
none
Vendor
linux
Opis źródłowy (NVD)

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauth_info is not allocated. This patch add KSMBD_SESS_NEED_SETUP status of connection to ignore session setup request if smb2 negotiate phase is not complete.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)69.6%
Opublikowano (NVD)2025-04-16 15:15:56 UTC
Ostatnia modyfikacja (NVD)2026-10-08 00:46:56 UTC
Referencje